
fluXtore Funnel Builder Security & Risk Analysis
wordpress.org/plugins/fluxtoreEasily create highly converting sales funnels!
Is fluXtore Funnel Builder Safe to Use in 2026?
Generally Safe
Score 99/100fluXtore Funnel Builder has a strong security track record. Known vulnerabilities have been patched promptly.
The fluxtore plugin v1.6.5 presents a mixed security posture. While it demonstrates good practices in areas like output escaping and prepared statement usage for SQL queries, significant concerns arise from its attack surface. A substantial portion of its AJAX handlers lack authentication checks, creating a direct path for unauthorized actions. The taint analysis further highlights critical risks with unsanitized paths, particularly in flows with high severity.
The vulnerability history, while showing no currently unpatched CVEs, reveals a past medium vulnerability attributed to missing authorization. This pattern, combined with the current finding of unprotected AJAX handlers, suggests a recurring issue with authorization controls in the plugin's development. The presence of the `unserialize` function is also a notable concern that could lead to deserialization vulnerabilities if user-supplied data is processed without proper validation.
In conclusion, fluxtore v1.6.5 has strengths in its general code quality regarding SQL and output handling. However, the significant number of unprotected AJAX endpoints and critical taint flows involving unsanitized paths represent serious security weaknesses that require immediate attention. The past vulnerability history reinforces the need for robust authorization checks.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flows
- Unsanitized paths in taint flows
- Use of unserialize function
- Past medium vulnerability (Missing Auth)
- Low capability check count
fluXtore Funnel Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
fluXtore <= 1.6.0 - Missing Authorization
fluXtore Funnel Builder Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
fluXtore Funnel Builder Attack Surface
AJAX Handlers 22
Shortcodes 2
WordPress Hooks 85
Maintenance & Trust
fluXtore Funnel Builder Maintenance & Trust
Maintenance Signals
Community Trust
fluXtore Funnel Builder Alternatives
FunnelKit – Funnel Builder for WooCommerce Checkout
funnel-builder
Create high-converting WooCommerce checkout pages, WooCommerce thank you pages & sales funnels with the highest-rated WordPress funnel builder.
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce
cartflows
1 WordPress funnel builder & WooCommerce checkout plugin. Boost AOV with one-click upsells, order bumps & high-converting checkout pages.
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution
shopengine
WooCommerce builder for Elementor and Gutenberg. It offers product templates, product sliders, shopping cart, quick view, Woo wishlist, product filter …
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
woolentor-addons
ShopLentor – More than a WooCommerce builder. A complete growth plugin to boost conversions, UX, and sales for your store.
fluXtore Funnel Builder Developer Profile
1 plugin · 100 total installs
How We Detect fluXtore Funnel Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fluxtore/assets/admin-script.js/wp-content/plugins/fluxtore/assets/js/vendor/sweetalert.min.js/wp-content/plugins/fluxtore/assets/admin-script.js/wp-content/plugins/fluxtore/assets/js/vendor/sweetalert.min.jsfluxtore/assets/admin-script.js?ver=fluxtore/assets/js/vendor/sweetalert.min.js?ver=HTML / DOM Fingerprints
fluxtore_script_vars